Social Engineering Fraud and Your Crime Policy
19 July 2026

PA single uninsured assault claim can easily reach $250,000 to $500,000 when you factor in medical expenses, legal defense, lost wages, and pain-and-suffering damages. Jury awards in nightclub assault cases have exceeded seven figures with increasing frequency. Without A&B coverage, those costs come directly out of your business assets, and for most bar owners, that means closing the doors permanently.

A single email cost a mid-sized construction firm $380,000 last year. The CFO received what looked like a routine wire transfer request from the company's general contractor, complete with matching letterhead and a spoofed email address that was off by one character. The money was gone in minutes. When the company filed a claim under their commercial crime policy, the insurer denied it. The reason? The CFO voluntarily initiated the transfer. No one hacked the system. No one broke in. Someone simply asked nicely, and it worked.


This scenario plays out thousands of times a year across every industry, and the gap between what business owners think their crime policy covers and what it actually covers is enormous. Social engineering fraud and your crime policy may not align the way you assume, and that disconnect can be financially devastating. If you operate in a high-risk sector like construction, hospitality, trucking, or cannabis, where large wire transfers and vendor payments are routine, understanding exactly where your coverage begins and ends isn't optional. It's survival.

Understanding Social Engineering in Modern Business

Social engineering is fraud that targets people, not systems. The attacker doesn't need to crack a firewall or install malware. They just need one person in your organization to believe a lie long enough to move money, share credentials, or hand over sensitive data.


The scale of this problem has exploded. Reported losses to imposter scams reached a record $3.5 billion in 2025, nearly tripling over just a few years. These aren't just attacks on Fortune 500 companies. Small and mid-sized businesses, especially those in industries with complex vendor relationships and frequent payments, are prime targets.


The reason is straightforward: high-risk businesses often deal with multiple subcontractors, shifting project timelines, and urgent payment requests. A nightclub owner paying a new liquor distributor, a trucking company wiring fuel advances, a cannabis operation settling with a packaging supplier - these are all moments where a well-crafted fake request can slip through.


Common Tactics: Phishing, Spoofing, and Business Email Compromise


The FBI's Internet Crime Complaint Center has documented almost $8.5 billion lost to business email compromise over a recent three-year span. BEC attacks are the most financially damaging form of social engineering, and they come in several flavors.


Phishing emails cast a wide net, sending thousands of messages hoping a few people click. Spear phishing is more targeted: the attacker researches your company, learns who handles payments, and crafts a convincing message. Spoofing involves faking a sender's email address or phone number so the communication appears to come from a trusted source, like your CEO, your bank, or a long-time vendor.


Business email compromise takes it further. The attacker either hacks into a real email account or creates a near-identical one, then inserts themselves into an existing email thread about a legitimate payment. They change the bank routing information and wait. The money lands in their account, and by the time anyone notices, it's been moved offshore. BEC attacks have become a problem that security leaders simply cannot ignore, given how effectively they bypass traditional email security tools.


The Psychological Element of Fraud


What makes social engineering so effective isn't technology. It's psychology. Attackers exploit authority, urgency, and trust. A request that appears to come from the CEO carries weight. A message marked "urgent" or "confidential" short-circuits normal verification steps.


Fraudsters also study timing. They strike during month-end closings, right before holidays, or during leadership transitions when normal approval chains are disrupted. In construction, they'll target the window between project milestones when large payments are expected. In hospitality, they'll hit during event season when accounts payable teams are overwhelmed.


The human element is why these attacks succeed even in organizations with good cybersecurity. Your firewall is irrelevant when your controller voluntarily sends a wire because they believe they're following legitimate instructions.

How Crime Policies Address Fraudulent Transfers

Most commercial crime policies were written for a different era of fraud: employee theft, forgery, robbery. They cover situations where someone takes your money without your knowledge or consent. Social engineering creates a gray area because your employee does know about the transfer. They authorized it. They just did so based on false information.


This distinction matters enormously when you file a claim. Standard crime policies typically include coverage for employee dishonesty, forgery, computer fraud, and funds transfer fraud. But the definitions in these policies are narrow, and insurers interpret them strictly.


Standard Crime Coverage vs. Social Engineering Endorsements


A standard crime policy's computer fraud provision covers losses resulting from unauthorized access to your computer systems. If a hacker breaks into your banking portal and moves money, that's covered. If someone emails your bookkeeper a fake invoice and your bookkeeper processes it through normal channels, that's not unauthorized computer access. It's a human being doing their job based on bad information.


This is where a social engineering endorsement becomes critical. This endorsement, sometimes called a fraudulent impersonation endorsement, specifically covers losses that occur when an employee is tricked into sending money by someone impersonating a vendor, executive, or client. Without it, you're likely looking at a denied claim.


The catch: these endorsements often come with sublimits. Your crime policy might carry $1 million in coverage, but the social engineering endorsement may cap out at $100,000 or $250,000. That's a painful surprise when you've lost $500,000 to a BEC scam. Brokers at firms like GrayStone Insurance Group regularly see clients who didn't realize their endorsement limits were a fraction of their overall policy, and closing that gap before an incident happens is exactly the kind of detail that experienced brokers catch.


The Difference Between Computer Fraud and Voluntary Parting


The legal concept that trips up most claims is called "voluntary parting." If your employee willingly initiates a transfer, even under false pretenses, many policies exclude the loss. The insurer's argument: no one forced the transfer. Your employee chose to send the money.


Court decisions on this issue have gone both ways, and the landscape of case law continues to evolve. Some courts have sided with policyholders, arguing that consent obtained through deception isn't true consent. Others have upheld the voluntary parting exclusion. The safest approach is to not rely on a court fight. Get the endorsement, negotiate adequate limits, and make sure your policy language explicitly addresses impersonation-based fraud.

Comparison of Coverage Scenarios

Coverage Comparison Table: Standard vs. Enhanced Policy

Scenario Standard Crime Policy Crime Policy with SE Endorsement
Employee embezzlement Covered Covered
Hacker accesses bank portal, transfers funds Covered (computer fraud) Covered (computer fraud)
Fake vendor invoice processed by AP team Likely denied (voluntary parting) Covered up to endorsement sublimit
CEO impersonation email triggers wire transfer Likely denied Covered up to endorsement sublimit
Spoofed phone call from "bank" requesting transfer Likely denied Covered if endorsement includes voice phishing
Vendor email hacked, routing info changed Gray area: depends on policy language Covered
Typical sublimit N/A $100K - $500K (varies by carrier)

The gap between columns two and three is where most businesses get burned. If your crime policy doesn't have a social engineering endorsement, or if the endorsement limit is too low, you're carrying more risk than you probably realize.

Key Requirements for a Successful Claim

Even with the right endorsement in place, insurers won't simply write a check. You need to demonstrate that your organization followed reasonable procedures and can document the loss thoroughly.


The Importance of Verification Protocols


Nearly every social engineering endorsement includes a condition: the insured must have verification procedures in place and must have followed them. If your policy requires callback verification for wire transfers over $10,000 and your team skipped that step, the claim can be denied.


Practical verification protocols include requiring a phone call to a known number (not the number in the suspicious email) for any payment change or new payment over a threshold, dual authorization for wire transfers, and a mandatory waiting period for new vendor banking information. These aren't just insurance requirements. The 2024 ACFE report on occupational fraud found that organizations with strong internal controls detected fraud faster and lost significantly less money.


GrayStone Insurance Group's brokers often help clients design verification protocols that satisfy their policy conditions while remaining practical for day-to-day operations. A protocol that's too cumbersome gets ignored, which defeats the purpose entirely.


Documentation Needed After a Loss


If you do suffer a social engineering loss, your insurer will want specific documentation:


  • The original fraudulent communication (emails, texts, voicemails)
  • Internal records showing who authorized the payment and when
  • Evidence that verification procedures were in place and followed
  • Bank records showing the transfer
  • A police report filed promptly
  • Communication with your bank about recovery efforts
  • A timeline of events from initial contact to discovery


Speed matters. The faster you notify your bank and insurer, the better your chances of recovering funds and getting your claim processed. Many policies have strict reporting windows, sometimes as short as 30 days from discovery.

Frequently Asked Questions About Fraud Insurance

Does my general liability policy cover social engineering losses? No. General liability covers bodily injury and property damage claims from third parties. Fraud losses require a commercial crime policy, and social engineering specifically requires an endorsement on that crime policy.


How much does a social engineering endorsement cost? For most small to mid-sized businesses, the endorsement adds $500 to $2,500 annually to your crime policy premium, depending on your industry, revenue, and the sublimit you choose. Given that average BEC losses run into six figures, it's one of the most cost-effective coverages available.


Can I increase the sublimit on my social engineering endorsement? Yes, though higher limits mean higher premiums and often stricter verification requirements. Some carriers will offer $500,000 or even $1 million sublimits for businesses that demonstrate strong internal controls.


Are cryptocurrency-related social engineering losses covered? This varies significantly by carrier. Most standard endorsements were written with traditional wire transfers in mind. If your business handles crypto transactions, discuss this specifically with your broker.


Does cyber liability insurance cover social engineering? Some cyber policies include limited social engineering coverage, but it's typically secondary to what a crime policy endorsement provides. Don't assume your cyber policy fills this gap without reviewing the specific language.


Will my claim be denied if one employee skipped the verification step? Possibly. Insurers scrutinize whether procedures were consistently followed. A single lapse can jeopardize a claim, which is why training and enforcement matter as much as having the protocol on paper.

The Bottom Line for Your Business Security

Your crime policy is only as strong as its weakest coverage provision, and for most businesses, social engineering is that weak point. The standard policy wasn't built for a world where a convincing email can drain your operating account in an afternoon.


The fix isn't complicated, but it requires attention. Get a social engineering endorsement with adequate limits. Build verification protocols your team will actually follow. Train your staff to recognize impersonation attempts. And review your policy annually, because the threats evolve and your coverage should keep pace.


If you're in a high-risk industry where large payments, multiple vendors, and tight timelines are the norm, this isn't something to put off. Talk to a broker who understands the specific fraud risks in your sector, review your crime policy's current endorsements and sublimits, and close the gaps before someone else finds them first.

Chad Kramer
CEO · Licensed Author
Search
INDEX
Switching Agents Mid-Term and the Broker of Record Letter
19 July 2026
Switch insurance agents mid-term with a Broker of Record letter. Learn the BOR process, timelines, benefits, and how to change brokers without losing coverage.
What to Do After a Large Commercial Claim
19 July 2026
Learn what to do after a large commercial insurance claim, from documenting damage and filing claims to maximizing recovery and rebuilding your business.
Umbrella Limits: How Much Excess Liability Is Enough
19 July 2026
Learn how much umbrella insurance you need to protect your assets. Compare coverage limits, costs, and excess liability options for businesses.
Get a quote

A specialist reviews every submission personally.

ABOUT THE AUTHOR:

CHAD KRAMER

I started GrayStone Insurance Group in 2018 with a simple conviction: the businesses everyone else turns away deserve a broker who won't. What began as a one-person operation has grown into a specialty commercial brokerage with offices across the country — but the mission hasn't changed. We find solutions for high-risk and hard-to-place businesses when other agencies run the other way.


I built this agency on integrity, hard work, and the tenacity to do the hard things well. Through our access to Excess & Surplus and specialty markets, my team and I place coverage standard carriers can't — and I treat every client's business like my own.

If you've been declined, non-renewed, or told your business is too complicated to insure, let's talk.

Share this article